Tag: Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: MacOS Bypass Flaw Lets Attackers Sign Malicious Code as Apple
What is the Issue: Due to a flaw in Apple’s code-signing API, hackers have been able to manipulate the code-signing process to enter malicious code into MacOS systems. Third-party security tools were unable to detect the issue as the malicious...
Cybersecurity Threat Advisory: Adobe Flash Zero Day Patch
What is the Issue: Adobe has recently released an emergency patch for a Flash Zero-Day vulnerability, that when exploited properly can allow an attacker to execute arbitrary code, and enable information disclosure. Most current web browsers block Adobe Flash all...
Cybersecurity Threat Advisory Google Chrome Content Security Policy
What is the Issue? Chrome’s security team described the issue as the web browser’s incorrect handling of CSP headers (CVE-2018-6148). They noted on their blog – “Access to bug details and links may be kept restricted until a majority of...
Cybersecurity Threat Advisory: Zip Slip Critical Flaw Hits Thousands of Open-Source Projects
What is the Issue? Security firm Snyk has disclosed a widespread and critical flaw in multiple archive file-extraction libraries found in thousands of open-source web application projects from HP, Amazon, Apache, Oracle, LinkedIn, Twitter and others. Zip Slip is a...
Cybersecurity Threat Advisory: DHS Releases “Joanap” and “Brambul” Malware Indicators
What is the Issue: On Tuesday May 29, the Department of Homeland Security (DHS) and Federal Bureau of Investigation (FBI) released a comprehensive report on malware associated with North Korean Government cyber activity. The report details a remote access tool...
Cybersecurity Threat Advisory: Attackers Using GDPR Email Alerts to Conduct Phishing Attacks
What is the Issue: With the EU rolling out new General Data Protection Regulation (GDPR) Laws on May 25th, many internet scammers have been using these laws to steal personal information, by sending fraudulent emails claiming to be from legitimate...
Cybersecurity Threat Advisory: Attackers Target Home and Office Routers and Network Devices
What is the issue: Cisco Talos Intelligence Group recently identified a new malware, known as VPNFilter, which may have infected upwards of 500,000 routers and network-attached storage devices (NAS) across the globe with malicious software. Most of these are small...
Cybersecurity Threat Advisory: Adobe’s Second Wave of Security Updates
What is the Issue: This week, Adobe has identified 47 vulnerabilities, 24 of which were found to be critical and are at high risk of exploitation. The vulnerabilities found in Adobe software such as Acrobat & Reader, as well as...